CVE-2019-17567
MEDIUMApache HTTP Server 2.4.6-2.4.46 - HTTP Request Smuggling via mod_proxy_wstunnel
Title source: llmDescription
Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.
References (11)
Core 11
Core References
Mailing List mailing-list
https://lists.apache.org/thread.html/r90f693a5c9fb75550ef1412436d5e682a5f845beb427fa6f23419a3c%40%3Cannounce.httpd.apache.org%3E
Mailing List mailing-list
https://lists.apache.org/thread.html/r7f2b70b621651548f4b6f027552f1dd91705d7111bb5d15cda0a68dd%40%3Cdev.httpd.apache.org%3E
Mailing List, Mitigation, Third Party Advisory mailing-list
http://www.openwall.com/lists/oss-security/2021/06/10/2
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202107-38
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/
Mailing List mailing-list
https://lists.debian.org/debian-lts-announce/2024/05/msg00013.html
Release Notes, Vendor Advisory
http://httpd.apache.org/security/vulnerabilities_24.html
Mailing List, Vendor Advisory
https://lists.apache.org/thread.html/re026d3da9d7824bd93b9f871c0fdda978d960c7e62d8c43cba8d0bf3%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
https://security.netapp.com/advisory/ntap-20210702-0001/
Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html
Scores
CVSS v3
5.3
EPSS
0.5973
EPSS Percentile
99.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Details
CWE
CWE-444
Status
published
Products (8)
apache/http_server
2.4.6 - 2.4.46
fedoraproject/fedora
34
fedoraproject/fedora
35
oracle/enterprise_manager_ops_center
12.4.0.0
oracle/instantis_enterprisetrack
17.1
oracle/instantis_enterprisetrack
17.2
oracle/instantis_enterprisetrack
17.3
oracle/zfs_storage_appliance_kit
8.8
Published
Jun 10, 2021
Tracked Since
Feb 18, 2026